Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1106 Native API |
GroupAPT38 | APT38 has used the Windows API to execute code within a victim's system. |
| T1106 Native API |
GroupSideCopy | SideCopy has executed malware by calling the API function `CreateProcessW`. |
| T1106 Native API |
GroupKimsuky | Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts. |
| T1106 Native API |
GroupGorgon Group | Gorgon Group malware can leverage the Windows API call, CreateProcessA(), for execution. |
| T1106 Native API |
GroupmenuPass | menuPass has used native APIs including |
| T1106 Native API |
GroupGamaredon Group | Gamaredon Group malware has used |
| T1106 Native API |
GroupSandworm Team | Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`. |
| T1106 Native API |
GroupMustang Panda | Mustang Panda has used various Windows API calls during execution and defense evasion. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDABroadcomEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Sophos Mustang Panda PLUGXTrend Micro Mustang Panda Earth Preta Toneshell February 2025ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1106 Native API |
GroupAPT37 | APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection. |
| T1106 Native API |
GroupHigaisa | Higaisa has called various native OS APIs. |
| T1106 Native API |
GroupTropic Trooper | Tropic Trooper has used multiple Windows APIs including HttpInitialize, HttpCreateHttpHandle, and HttpAddUrl. |
| T1106 Native API |
GroupBlackTech | BlackTech has used built-in API functions. |
| T1106 Native API |
GroupTurla | Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes. |
| T1106 Native API |
GroupTA505 | TA505 has deployed payloads that use Windows API calls on a compromised host. |
| T1106 Native API |
GroupChimera | Chimera has used direct Windows system calls by leveraging Dumpert. |
| T1106 Native API |
GroupMedusa Group | Medusa Group has leveraged Windows Native API functions to execute payloads. |
| T1106 Native API |
GroupToddyCat | ToddyCat has used `WinExec` to execute commands received from C2 on compromised hosts. |
| T1106 Native API |
GroupLazarus Group | Lazarus Group has used the Windows API |
| T1106 Native API |
GroupSilence | Silence has leveraged the Windows API, including using CreateProcess() or ShellExecute(), to perform a variety of tasks. |
| T1106 Native API |
GroupWIRTE | WIRTE has used the `RtlIpv4StringToAddressA` to convert IP-formatted string to a byte array. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.